This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

IE6 pop up to random sites.

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Yesterday I noticed a new process in the task manager called Bbuloa.exe I tried looking for information about it but no luck. In addition
my Avira Antivirus Guard denied access to TR\Spy.70656.37 just yesterday

Whenever I try to end process for Bbuloa.exe, it pops back up in 10-20minutes usually. In addition it takes up to 50% of my CPU usage at times.

I ran an Avira Scan today, but no luck it came up clean. The IE popups seem to occur everytime I run an Avira Scan. Should I be worried about the Bbuloa.exe which is what i think is causing the IE popups.

Here is the Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:38:46 PM, on 6/11/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Bbuloa.exe
C:\WINDOWS\system32\ZDWLAN.EXE
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Documents and Settings\818\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\SpywareGuard\sgmain.exe
C:\Program Files\SpywareGuard\sgbhp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\818\My Documents\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://ca.search.yahoo.com/search?fr=mcafee&p=%s
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll
O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97} - C:\WINDOWS\System32\ckvnz.dll (file missing)
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: {9fe64c93-dce7-a1cb-de04-5e5fdeeaca9e} - {e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9} - C:\WINDOWS\System32\olmqewdh.dll (file missing)
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
O4 - HKLM\..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
O4 - HKLM\..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe /StartUp
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [ZDWLAN.EXE] ZDWLAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe /waitservice
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\818\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [M5T8QL3YW3] C:\DOCUME~1\818\LOCALS~1\Temp\Bjw.exe
O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201
O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204
O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203
O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs:
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: pmnmmli - pmnmmli.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: CeEPwrSvc - COMPAL ELECTRONIC INC. - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: nProtect GameGuard Service (npggsvc) - Unknown owner - C:\WINDOWS\System32\GameMon.des.exe (file missing)
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe

–
End of file - 9260 bytes
Hi mystic_hs, welcome to the forum.

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.

Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.

  • Double click on the file you downloaded. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER will not run in normal windows, please run it in Safe Mode




Next

Download OTL to your desktop.
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    %systemroot%\system32\drivers\*.sys /90
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • GMER log
  • both OTL logs
Thanks
I deleted Bbuloa.exe from the WINDOWS two days ago before you told me to run any scans and everything seems back to normal.
Here are the scan results that you requested.

Gmer:

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-06-12 13:41:57
Windows 5.1.2600 Service Pack 2
Running: 9bh453fi.exe; Driver: C:\DOCUME~1\818\LOCALS~1\Temp\uxqoqaob.sys


—- System - GMER 1.0.15 —-

SSDT F7BFAD26 ZwCreateKey
SSDT F7BFAD1C ZwCreateThread
SSDT F7BFAD2B ZwDeleteKey
SSDT F7BFAD35 ZwDeleteValueKey
SSDT F7BFAD3A ZwLoadKey
SSDT F7BFAD08 ZwOpenProcess
SSDT F7BFAD0D ZwOpenThread
SSDT F7BFAD44 ZwReplaceKey
SSDT F7BFAD3F ZwRestoreKey
SSDT F7BFAD30 ZwSetValueKey
SSDT F7BFAD17 ZwTerminateProcess

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\Tcp FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\Udp FILTNT.SYS (Virtual Firewall driver/Agnitum)
AttachedDevice \Driver\Tcpip \Device\RawIp FILTNT.SYS (Virtual Firewall driver/Agnitum)

—- EOF - GMER 1.0.15 —-

OTL:

OTL logfile created on: 6/13/2010 11:32:26 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 49.12 Gb Free Space | 65.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\WINDOWS\system32\ZDWLAN.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - c:\Program Files\McAfee\SiteAdvisor\sahook.dll (McAfee, Inc.)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe (Apache Software Foundation)
SRV - (CeEPwrSvc) – C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (OutpostFirewall) – C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ZD1211U(ZyDAS)) WLAN 802.11g USB2.0 Adapter(ZyDAS) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (RT2500) – C:\WINDOWS\system32\drivers\RT2500.sys (Ralink Technology Inc.)
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (EPOWER) – C:\WINDOWS\system32\drivers\hkdrv.sys (Compal Electronic Inc.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}) – C:\WINDOWS\system32\drivers\wA301a.sys (Intel Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEPIOMngr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (wlluc48) – C:\WINDOWS\system32\drivers\wlluc48.sys (Lucent Technologies)
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys ()
DRV - (wlags48b) – C:\WINDOWS\system32\drivers\wlags48b.sys (Agere Systems)
DRV - (PROTECT.DLL) Outpost Firewall PlugIn (PROTECT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Protect.dll (Agnitum)
DRV - (FTPFILT.DLL) Outpost Firewall PlugIn (FTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Ftpfilt.dll (Agnitum)
DRV - (IMAPFILT.DLL) Outpost Firewall PlugIn (IMAPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Imapfilt.dll (Agnitum)
DRV - (NNTPFILT.DLL) Outpost Firewall PlugIn (NNTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Nntpfilt.dll (Agnitum)
DRV - (CONTENT.DLL) Outpost Firewall PlugIn (CONTENT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Content.dll (Agnitum)
DRV - (MAILFILT.DLL) Outpost Firewall PlugIn (MAILFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Mailfilt.dll (Agnitum)
DRV - (POP3FILT.DLL) Outpost Firewall PlugIn (POP3FILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Pop3filt.dll (Agnitum)
DRV - (ADBLOCK.DLL) Outpost Firewall PlugIn (ADBLOCK.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\ADBLOCK.dll (Agnitum)
DRV - (HTMLFILT.DLL) Outpost Firewall PlugIn (HTMLFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Htmlfilt.dll (Agnitum)
DRV - (HTTPFILT.DLL) Outpost Firewall PlugIn (HTTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Httpfilt.dll (Agnitum)
DRV - (DNSCACHE.DLL) Outpost Firewall PlugIn (DNSCACHE.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Dnscache.dll (Agnitum)
DRV - (VFILT) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\2000\Filtnt.sys (Agnitum)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\Tbiosdrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..network.proxy.http: "209.191.82.40"
FF - prefs.js..network.proxy.http_port: 80

FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/12/30 18:15:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/05/31 19:25:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/04 20:45:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/02 12:23:50 | 000,000,000 | —D | M]

[2009/04/06 18:26:55 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Extensions
[2010/06/11 16:27:32 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions
[2008/03/13 14:34:44 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{1650a312-02bc-40ee-977e-83f158701739}(2)
[2010/04/27 20:14:36 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/01/29 11:42:02 | 000,000,000 | —D | M] (Adblock) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/04/06 18:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed]
[2009/04/05 15:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed](2).org
[2008/03/12 22:33:52 | 000,002,386 | —- | M] () – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\searchplugins\siteadvisor.xml
[2010/06/11 16:27:32 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 12:23:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2007/12/30 18:15:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/02 12:23:08 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2008/07/19 18:03:42 | 000,240,768 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 babe.the-killer.bz
O1 - Hosts: 127.0.0.1 www.babe.the-killer.bz
O1 - Hosts: 127.0.0.1 babe.k-lined.com
O1 - Hosts: 127.0.0.1 www.babe.k-lined.com
O1 - Hosts: 127.0.0.1 did.i-used.cc
O1 - Hosts: 127.0.0.1 www.did.i-used.cc
O1 - Hosts: 127.0.0.1 coolwwwsearch.com
O1 - Hosts: 127.0.0.1 www.coolwwwsearch.com
O1 - Hosts: 127.0.0.1 coolwebsearch.com
O1 - Hosts: 127.0.0.1 www.coolwebsearch.com
O1 - Hosts: 127.0.0.1 hi.studioaperto.net
O1 - Hosts: 127.0.0.1 www.hi.studioaperto.net
O1 - Hosts: 127.0.0.1 webbrowser.tv
O1 - Hosts: 127.0.0.1 www.webbrowser.tv
O1 - Hosts: 127.0.0.1 wazzupnet.com
O1 - Hosts: 127.0.0.1 www.wazzupnet.com
O1 - Hosts: 127.0.0.1 gueb.com
O1 - Hosts: 127.0.0.1 www.gueb.com
O1 - Hosts: 127.0.0.1 kabex.com
O1 - Hosts: 127.0.0.1 www.kabex.com
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1 www.hityou.com
O1 - Hosts: 127.0.0.1 miosearch.com
O1 - Hosts: 127.0.0.1 www.miosearch.com
O1 - Hosts: 8421 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (no name) - {B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97} - C:\WINDOWS\System32\ckvnz.dll File not found
O2 - BHO: (no name) - {e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9} - C:\WINDOWS\System32\olmqewdh.dll File not found
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe File not found
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe File not found
O4 - HKLM..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe File not found
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe File not found
O4 - HKLM..\Run: [ZDWLAN.EXE] C:\WINDOWS\System32\ZDWLAN.exe ()
O4 - HKCU..\Run: [M5T8QL3YW3] C:\DOCUME~1\818\LOCALS~1\Temp\Bjw.exe File not found
O4 - HKCU..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe File not found
O4 - Startup: C:\Documents and Settings\818\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-0000-0000-000000000000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\pmnmmli: DllName - pmnmmli.dll - File not found
O24 - Desktop WallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/27 13:43:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2003/08/27 13:43:00 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010/06/10 23:56:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MainType
[2010/06/10 21:05:30 | 000,000,000 | —D | C] – C:\cygwin2
[2010/06/10 17:08:32 | 000,000,000 | —D | C] – C:\cygwin
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Proxima Software
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Obsidium
[2010/06/09 21:42:35 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\FontCreator
[2010/06/07 18:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Desktop\rks_trial002a
[2010/05/22 22:06:54 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Local Settings\Application Data\Temp
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/06/13 10:37:43 | 000,039,847 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.py
[2010/06/13 02:11:06 | 000,000,970 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/06/13 02:11:00 | 000,000,274 | -H– | M] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/13 01:58:00 | 000,000,242 | -H– | M] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/13 00:34:28 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/13 00:34:07 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/12 22:30:06 | 007,340,032 | —- | M] () – C:\Documents and Settings\818\ntuser.dat
[2010/06/12 22:29:40 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\818\ntuser.ini
[2010/06/12 22:29:20 | 001,575,706 | -H– | M] () – C:\Documents and Settings\818\Local Settings\Application Data\IconCache.db
[2010/06/12 22:11:01 | 000,000,918 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/06/12 20:54:30 | 000,045,446 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.py
[2010/06/12 18:38:20 | 000,028,640 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/12 18:31:27 | 014,957,056 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/12 18:30:49 | 014,957,056 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/12 12:55:26 | 062,861,312 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/06/12 11:02:48 | 000,129,296 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/12 00:16:33 | 000,054,975 | —- | M] () – C:\Documents and Settings\818\Desktop\server.py
[2010/06/11 18:32:55 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/11 17:56:29 | 000,089,088 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 17:48:03 | 000,000,514 | —- | M] () – C:\Documents and Settings\818\Application Data\turing_files.ini
[2010/06/11 00:35:02 | 000,000,151 | —- | M] () – C:\WINDOWS\fcp5.cfg
[2010/06/10 21:46:45 | 000,000,154 | —- | M] () – C:\WINDOWS\mt3.cfg
[2010/06/10 00:18:40 | 000,001,026 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/09 18:39:55 | 000,020,309 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.py
[2010/06/09 18:37:59 | 000,012,255 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.pyc
[2010/06/09 18:32:35 | 000,019,313 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.pyc
[2010/06/08 17:16:31 | 000,002,279 | —- | M] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/06/08 16:42:08 | 000,007,563 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.pyc
[2010/06/08 16:17:01 | 000,003,914 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.pyc
[2010/06/07 23:30:50 | 000,005,292 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.py
[2010/06/07 00:29:25 | 000,303,685 | —- | M] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/06/04 21:01:12 | 000,046,765 | —- | M] () – C:\Documents and Settings\818\Desktop\server_back.py
[2010/05/30 13:09:39 | 023,769,026 | —- | M] () – C:\Documents and Settings\818\Desktop\absurd64.zip
[2010/05/27 21:51:20 | 000,027,136 | —- | M] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/27 21:00:42 | 000,022,528 | —- | M] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/27 17:53:17 | 000,139,264 | —- | M] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:15:26 | 000,033,792 | —- | M] () – C:\Documents and Settings\818\My Documents\The Picture of Dorian Gray.doc
[2010/05/23 10:24:49 | 000,040,441 | —- | M] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/18 21:25:45 | 000,001,634 | —- | M] () – C:\Documents and Settings\818\Desktop\config.py
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/06/12 18:31:24 | 014,957,056 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/12 12:50:27 | 014,957,056 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/11 18:32:54 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/10 23:42:14 | 000,000,274 | -H– | C] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/10 23:42:12 | 000,000,242 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/10 21:46:45 | 000,000,154 | —- | C] () – C:\WINDOWS\mt3.cfg
[2010/06/09 21:43:00 | 000,000,151 | —- | C] () – C:\WINDOWS\fcp5.cfg
[2010/06/07 00:29:23 | 000,303,685 | —- | C] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/05/27 17:45:49 | 000,139,264 | —- | C] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:32:01 | 000,022,528 | —- | C] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/24 12:53:01 | 000,027,136 | —- | C] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/23 10:24:47 | 000,040,441 | —- | C] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/22 22:08:17 | 000,002,279 | —- | C] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/05/22 22:06:52 | 000,000,970 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/05/22 22:06:51 | 000,000,918 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/05/18 21:15:52 | 000,001,634 | —- | C] () – C:\Documents and Settings\818\Desktop\config.py
[2009/06/01 21:16:05 | 000,000,031 | —- | C] () – C:\WINDOWS\Caligari.ini
[2009/05/14 22:23:40 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS74.DLL
[2008/05/19 14:12:46 | 000,000,051 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2008/04/29 20:58:46 | 000,041,296 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2007/12/31 13:22:28 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2007/12/30 12:55:53 | 000,000,294 | -HS- | C] () – C:\WINDOWS\System32\bcdnfblg.ini
[2007/12/23 14:48:05 | 000,000,096 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/16 18:53:57 | 000,001,066 | —- | C] () – C:\WINDOWS\pae.ini
[2007/02/03 11:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/05 15:17:01 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2007/01/05 15:17:01 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/09/16 15:30:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/19 16:31:57 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2006/07/16 12:56:28 | 000,001,135 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/07/12 14:18:29 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2006/07/12 14:18:13 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/07/12 14:18:13 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/07/12 14:18:13 | 000,009,535 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/07/12 14:18:13 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/08/12 17:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/09/26 19:32:38 | 000,044,706 | —- | C] () – C:\WINDOWS\System32\ZDMLu.INI
[2004/09/26 19:25:52 | 000,023,506 | —- | C] () – C:\WINDOWS\System32\ZDMLa.INI
[2004/08/10 14:28:20 | 000,001,088 | —- | C] () – C:\WINDOWS\System32\ZDWlan.INI
[2004/03/23 19:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2004/03/05 18:00:58 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/03/05 18:00:26 | 000,827,392 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2003/09/01 13:51:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Installrt2500qa.dll
[2003/08/27 21:41:48 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/27 20:49:36 | 000,000,426 | —- | C] () – C:\WINDOWS\System32\Px.ini
[2003/08/27 20:47:54 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2003/08/27 20:47:53 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2003/08/27 20:47:53 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2003/08/27 20:47:53 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2003/08/27 20:25:44 | 000,000,000 | —- | C] () – C:\WINDOWS\CePMTray.INI
[2003/08/27 13:49:38 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/27 13:48:06 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/27 13:29:57 | 000,001,866 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/08/27 13:29:25 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/07/29 19:34:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEKPolicy.dll
[2003/07/23 21:35:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEPPolicy.dll
[2003/07/23 21:03:48 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\CeEPDefDat.dll
[2002/10/06 14:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 19:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 19:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 19:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/07/17 20:45:48 | 000,004,183 | —- | C] () – C:\WINDOWS\System32\drivers\TPIOMngr.sys
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2009/06/01 16:46:37 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Blender Foundation
[2009/09/06 22:40:24 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\FFSJ
[2010/06/11 18:04:46 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\FontCreator
[2009/04/02 23:48:51 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Graboid Inc
[2009/07/27 23:30:58 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\GrabPro
[2010/04/13 16:47:54 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\HAPedit
[2009/09/13 14:24:28 | 000,000,000 | -H-D | M] – C:\Documents and Settings\818\Application Data\ijjigame
[2003/08/27 20:53:21 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\InterTrust
[2006/07/12 14:25:44 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\InterVideo
[2008/07/20 21:34:56 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\MySQL
[2010/06/10 00:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Obsidium
[2008/11/24 01:27:54 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Opera
[2010/05/30 22:01:25 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Orbit
[2007/05/26 14:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\PlayFirst
[2008/07/17 14:56:06 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\postgresql
[2010/06/10 00:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Proxima Software
[2008/07/10 20:24:03 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Sony Setup
[2009/09/09 22:58:39 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Thinstall
[2008/12/07 19:53:37 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\TrueCrypt
[2007/12/30 12:53:32 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Uniblue
[2008/08/29 12:09:13 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Web Page Maker
[2009/02/23 20:28:55 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\WordWeb
[2007/05/11 00:53:17 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2007/12/31 13:20:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2009/10/20 18:42:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ijjigame
[2010/06/11 18:04:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MainType
[2006/09/21 19:13:41 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Messenger Plus!
[2007/05/26 14:33:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2009/04/19 13:00:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2006/07/12 14:21:22 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 1.job
[2006/07/12 14:21:23 | 000,000,258 | —- | M] () – C:\WINDOWS\Tasks\Registration reminder 3.job
[2010/06/13 01:58:00 | 000,000,242 | -H– | M] () – C:\WINDOWS\Tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
[2010/06/13 02:11:00 | 000,000,274 | -H– | M] () – C:\WINDOWS\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2004/08/03 23:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\system32\drivers\agp440.sys

< MD5 for: ATAPI.SYS >
[2002/08/29 08:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2002/08/29 08:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\I386\sp1.cab:atapi.sys
[2004/08/04 01:05:44 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2002/08/29 04:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2002/08/29 08:00:00 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\system32\drivers\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\system32\eventlog.dll
[2002/08/29 08:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2002/08/29 08:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | —- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 – C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2004/08/04 00:56:46 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\system32\scecli.dll
[2002/08/29 08:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[4 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2003/08/27 06:34:22 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2003/08/27 06:34:22 | 000,602,112 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2003/08/27 06:34:22 | 000,397,312 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %systemroot%\system32\drivers\*.sys /90 >

========== Files - Unicode (All) ==========
[2008/01/05 15:00:42 | 000,000,000 | —D | M](C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft
[2007/12/24 12:06:47 | 000,000,000 | —D | M](C:\Program Files\Common Files\M?crosoft\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft\Mіcrosoft
(C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:84098FD3
@Alternate Data Stream - 88 bytes -> C:\Auth.prof:SummaryInformation
@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD0CE449
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

Extras:

OTL Extras logfile created on: 6/13/2010 11:32:26 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 49.12 Gb Free Space | 65.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\opera.exe (Opera Software)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\WINDOWS\Downloaded Program Files\PurpleBean.exe" = C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Disabled:PurpleBean.exe – ()
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe" = C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Disabled:Reactor Application – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call – (Microsoft Corporation)
"C:\Python31\pythonw.exe" = C:\Python31\pythonw.exe:*:Enabled:pythonw – ()
"C:\Program Files\Kaiba Corp VDS\KCVDS.exe" = C:\Program Files\Kaiba Corp VDS\KCVDS.exe:*:Enabled:KCVDS – (Kaiba Corp)
"C:\cygwin\bin\XWin.exe" = C:\cygwin\bin\XWin.exe:*:Enabled:XWin – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2AFDE05E-934B-4A3A-B6A8-809A7A654EF8}" = Toshiba Registration
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3ad61ee5-81d2-4d7e-adef-da1dd37277d1}" = Python 3.1
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49371ACC-929A-48BB-AA5E-A35FE3D0CA5F}" = WLAN
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{666CF041-77BE-414E-9A9D-0A227E9B48F8}" = Norton™ Security Scan
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8318FEFD-F467-44D6-82B8-129374BFE9B1}" = Opera 9.62
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{DDC146FA-73E0-4FA1-A353-841EA14BF600}" = Drag'n Drop CD+DVD
"{EC86822D-3A20-11D5-801B-00E029348F40}" = SMSC IrCC Driver V5.1.2462.0 (WinXP)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agnitum Outpost Firewall 1.0" = Agnitum Outpost Firewall 1.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CANONBJ_Deinstall_CNMCP74.DLL" = Canon iP2200
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"GraphicsGale FreeEdition_is1" = GraphicsGale FreeEdition version 1.93.12
"Hamachi" = Hamachi 1.0.3.0
"InstallShield_{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"InstallShield_{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"InstallShield_{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"Kaiba Corp VDS_is1" = Kaiba Corp Virtual Duel System 1.16
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Orbit_is1" = Orbit Downloader
"RPG Maker 2003_is1" = RPG Maker 2003 v1.08
"RPG Maker VX RTP_is1" = RPG Maker VX RTP
"RPG Maker VX_is1" = RPG Maker VX
"SCAR 2.03_is1" = SCAR CDE 2.03
"Screen Recorder Gold" = Screen Recorder Gold
"SpriteForge_is1" = VE1.8-R1.9
"SpywareBlaster_is1" = SpywareBlaster v3.5.1
"SpywareGuard_is1" = SpywareGuard v2.2
"SystemRequirementsLab" = System Requirements Lab
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"TrueCrypt" = TrueCrypt
"VLC media player" = VLC media player 0.9.9
"WampServer 2_is1" = WampServer 2.0
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WLAN 802.11g USB2.0 Utility" = WLAN 802.11g USB2.0 Utility
"WordWeb" = WordWeb

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/11/2010 5:11:22 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 6:11:21 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 6:26:36 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/11/2010 6:29:40 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/11/2010 7:11:20 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 7:36:38 PM | Computer Name = YOUR-TH3IEUQTQB | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 6/12/2010 9:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/12/2010 10:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/13/2010 1:11:07 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/13/2010 2:11:05 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 7:35:53 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 11:03:27 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 12:49:35 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 12:56:05 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 2:34:19 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/13/2010 12:34:44 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2


< End of report >
Hi mystic_hs,

We have a bit more to do. You have some very old vulnerable Java installed.

Open Control Panel > Add/Remove Programs and uninstall

Java 2 Runtime Environment, SE v1.4.2
J2SE Runtime Environment 5.0 Update 3
Java™ 6 Update 3

Do not uninstall Java TM 6 Update 20 :yeah:


Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :

:OTL
O2 - BHO: (no name) - {B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97} - C:\WINDOWS\System32\ckvnz.dll File not found
O2 - BHO: (no name) - {e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9} - C:\WINDOWS\System32\olmqewdh.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O4 - HKCU..\Run: [M5T8QL3YW3] C:\DOCUME~1\818\LOCALS~1\Temp\Bjw.exe File not found
O20 - Winlogon\Notify\pmnmmli: DllName - pmnmmli.dll - File not found
[2010/06/10 23:42:14 | 000,000,274 | -H– | C] () – C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job
[2010/06/10 23:42:12 | 000,000,242 | -H– | C] () – C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job
O4 - HKLM..\Run: [] File not found

:Commands
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.

Next

Download and save to your desktop Malwarebytes Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Please post back with
  • OTL fix log
  • MBAM log
  • new OTL log, there will only be an OTL.txt this time.

Any problems?

Thanks
yes, i'm sorry, but i still haven't done everything u asked for yet. I really appreciate your help! Thanks!
new OTL:

OTL logfile created on: 6/16/2010 9:57:37 PM - Run 2
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 148.00 Mb Available Physical Memory | 31.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 50.25 Gb Free Space | 67.42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\WINDOWS\system32\ZDWLAN.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SpywareGuard\sgmain.exe ()
PRC - C:\Program Files\SpywareGuard\sgbhp.exe ()
PRC - C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
PRC - C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
PRC - C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\818\My Documents\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (McAfee SiteAdvisor Service) – C:\Program Files\McAfee\SiteAdvisor\McSACore.exe (McAfee, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (npggsvc) – C:\WINDOWS\System32\GameMon.des (INCA Internet Co., Ltd.)
SRV - (wampmysqld) – c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe ()
SRV - (wampapache) – c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe (Apache Software Foundation)
SRV - (CeEPwrSvc) – C:\Program Files\TOSHIBA\Power Management\CeEPwrSvc.exe (COMPAL ELECTRONIC INC.)
SRV - (DVD-RAM_Service) – C:\WINDOWS\system32\DVDRAMSV.exe (Matsushita Electric Industrial Co., Ltd.)
SRV - (OutpostFirewall) – C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)


========== Driver Services (SafeList) ==========

DRV - (avgntflt) – C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (ssmdrv) – C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (hamachi) – C:\WINDOWS\system32\drivers\hamachi.sys (LogMeIn, Inc.)
DRV - (avipbb) – C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgio) – C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (truecrypt) – C:\WINDOWS\system32\drivers\truecrypt.sys (TrueCrypt Foundation)
DRV - (SASKUTIL) – C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASDIFSV) – C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (LVUSBSta) – C:\WINDOWS\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINDOWS\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (SASENUM) – C:\Program Files\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (usbaudio) USB Audio Driver (WDM) – C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (ZD1211U(ZyDAS)) WLAN 802.11g USB2.0 Adapter(ZyDAS) – C:\WINDOWS\system32\drivers\ZD1211U.sys (ZyDAS Technology Corporation)
DRV - (RT2500) – C:\WINDOWS\system32\drivers\RT2500.sys (Ralink Technology Inc.)
DRV - (ZDPNDIS5) – C:\WINDOWS\system32\ZDPNDIS5.sys (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (EPOWER) – C:\WINDOWS\system32\drivers\hkdrv.sys (Compal Electronic Inc.)
DRV - (AR5211) – C:\WINDOWS\system32\drivers\ar5211.sys (Atheros Communications, Inc.)
DRV - (ApfiltrService) – C:\WINDOWS\system32\drivers\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (Pfc) – C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - ({E2B953A6-195A-44F9-9BA3-3D5F4E32BB55}) – C:\WINDOWS\system32\drivers\wA301a.sys (Intel Corporation)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (meiudf) – C:\WINDOWS\system32\drivers\meiudf.sys (Matsushita Electric Industrial Co.,Ltd.)
DRV - (AgereSoftModem) – C:\WINDOWS\system32\drivers\AGRSM.sys (Agere Systems)
DRV - (SrvcSSIOMngr) – C:\WINDOWS\system32\drivers\SSIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEPIOMngr) – C:\WINDOWS\system32\drivers\EPIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (SrvcEKIOMngr) – C:\WINDOWS\system32\drivers\EKIOMngr.sys (COMPAL ELECTRONIC INC.)
DRV - (wlluc48) – C:\WINDOWS\system32\drivers\wlluc48.sys (Lucent Technologies)
DRV - (SrvcTPIOMngr) – C:\WINDOWS\system32\drivers\TPIOMngr.sys ()
DRV - (wlags48b) – C:\WINDOWS\system32\drivers\wlags48b.sys (Agere Systems)
DRV - (PROTECT.DLL) Outpost Firewall PlugIn (PROTECT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Protect.dll (Agnitum)
DRV - (FTPFILT.DLL) Outpost Firewall PlugIn (FTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Ftpfilt.dll (Agnitum)
DRV - (IMAPFILT.DLL) Outpost Firewall PlugIn (IMAPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Imapfilt.dll (Agnitum)
DRV - (NNTPFILT.DLL) Outpost Firewall PlugIn (NNTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Nntpfilt.dll (Agnitum)
DRV - (CONTENT.DLL) Outpost Firewall PlugIn (CONTENT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Content.dll (Agnitum)
DRV - (MAILFILT.DLL) Outpost Firewall PlugIn (MAILFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Mailfilt.dll (Agnitum)
DRV - (POP3FILT.DLL) Outpost Firewall PlugIn (POP3FILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Pop3filt.dll (Agnitum)
DRV - (ADBLOCK.DLL) Outpost Firewall PlugIn (ADBLOCK.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\ADBLOCK.dll (Agnitum)
DRV - (HTMLFILT.DLL) Outpost Firewall PlugIn (HTMLFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Htmlfilt.dll (Agnitum)
DRV - (HTTPFILT.DLL) Outpost Firewall PlugIn (HTTPFILT.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Httpfilt.dll (Agnitum)
DRV - (DNSCACHE.DLL) Outpost Firewall PlugIn (DNSCACHE.DLL) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\Dnscache.dll (Agnitum)
DRV - (VFILT) – C:\Program Files\Agnitum\Outpost Firewall 1.0\Kernel\2000\Filtnt.sys (Agnitum)
DRV - (rtl8139) – C:\WINDOWS\system32\drivers\R8139n51.sys (Realtek Semiconductor Corporation)
DRV - (SMCIRDA) – C:\WINDOWS\system32\drivers\smcirda.sys (SMC)
DRV - (TBiosDrv) – C:\WINDOWS\system32\drivers\Tbiosdrv.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Secure Search"
FF - prefs.js..browser.search.defaulturl: "http://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;="
FF - prefs.js..browser.search.selectedEngine: "Secure Search"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.startup.homepage: "http://en-US.start2.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {B7082FAA-CB62-4872-9106-E42DD88EDE45}:3.1
FF - prefs.js..extensions.enabledItems: orbit_ffext@orbitdownloader:2.02
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "http://ca.search.yahoo.com/search?fr=mcafee&p;="
FF - prefs.js..network.proxy.http: "209.191.82.40"
FF - prefs.js..network.proxy.http_port: 80

FF - HKLM\software\mozilla\Firefox\Extensions\\{3112ca9c-de6d-4884-a869-9855de68056c}: C:\Documents and Settings\All Users\Application Data\Mozilla\Firefox Extensions\{3112ca9c-de6d-4884-a869-9855de68056c} [2007/12/30 18:15:12 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{B7082FAA-CB62-4872-9106-E42DD88EDE45}: C:\Program Files\McAfee\SiteAdvisor [2010/06/15 19:05:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/05/04 20:45:31 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/02 12:23:50 | 000,000,000 | —D | M]

[2009/04/06 18:26:55 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Extensions
[2010/06/11 16:27:32 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions
[2008/03/13 14:34:44 | 000,000,000 | —D | M] (McAfee SiteAdvisor) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{1650a312-02bc-40ee-977e-83f158701739}(2)
[2010/04/27 20:14:36 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/01/29 11:42:02 | 000,000,000 | —D | M] (Adblock) – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2009/04/06 18:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed]
[2009/04/05 15:06:07 | 000,000,000 | —D | M] – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\extensions\[removed](2).org
[2008/03/12 22:33:52 | 000,002,386 | —- | M] () – C:\Documents and Settings\818\Application Data\Mozilla\Firefox\Profiles\idbxdz08.default\searchplugins\siteadvisor.xml
[2010/06/14 17:54:59 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/05/02 12:23:59 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2007/12/30 18:15:25 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2010/05/02 12:23:08 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/06/16 21:51:58 | 000,002,027 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\McSiteAdvisor.xml

O1 HOSTS File: ([2008/07/19 18:03:42 | 000,240,768 | R— | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 babe.the-killer.bz
O1 - Hosts: 127.0.0.1 www.babe.the-killer.bz
O1 - Hosts: 127.0.0.1 babe.k-lined.com
O1 - Hosts: 127.0.0.1 www.babe.k-lined.com
O1 - Hosts: 127.0.0.1 did.i-used.cc
O1 - Hosts: 127.0.0.1 www.did.i-used.cc
O1 - Hosts: 127.0.0.1 coolwwwsearch.com
O1 - Hosts: 127.0.0.1 www.coolwwwsearch.com
O1 - Hosts: 127.0.0.1 coolwebsearch.com
O1 - Hosts: 127.0.0.1 www.coolwebsearch.com
O1 - Hosts: 127.0.0.1 hi.studioaperto.net
O1 - Hosts: 127.0.0.1 www.hi.studioaperto.net
O1 - Hosts: 127.0.0.1 webbrowser.tv
O1 - Hosts: 127.0.0.1 www.webbrowser.tv
O1 - Hosts: 127.0.0.1 wazzupnet.com
O1 - Hosts: 127.0.0.1 www.wazzupnet.com
O1 - Hosts: 127.0.0.1 gueb.com
O1 - Hosts: 127.0.0.1 www.gueb.com
O1 - Hosts: 127.0.0.1 kabex.com
O1 - Hosts: 127.0.0.1 www.kabex.com
O1 - Hosts: 127.0.0.1 hityou.com
O1 - Hosts: 127.0.0.1 www.hityou.com
O1 - Hosts: 127.0.0.1 miosearch.com
O1 - Hosts: 127.0.0.1 www.miosearch.com
O1 - Hosts: 8421 more lines…
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Easy-WebPrint) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll ()
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe File not found
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CeEKEY] C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe File not found
O4 - HKLM..\Run: [CeEPOWER] C:\Program Files\TOSHIBA\Power Management\CePMTray.exe File not found
O4 - HKLM..\Run: [Drag'n Drop CD+DVD] C:\Program Files\Drag'n Drop CD+DVD\BinFiles\DragDrop.exe File not found
O4 - HKLM..\Run: [Easy-PrintToolBox] C:\Program Files\Canon\Easy-PrintToolBox\BJPSMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe File not found
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe File not found
O4 - HKLM..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe File not found
O4 - HKLM..\Run: [Outpost Firewall] C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe (Agnitum)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe File not found
O4 - HKLM..\Run: [TPNF] C:\Program Files\TOSHIBA\TouchPad\TPTray.exe File not found
O4 - HKLM..\Run: [ZDWLAN.EXE] C:\WINDOWS\System32\ZDWLAN.exe ()
O4 - HKCU..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe File not found
O4 - Startup: C:\Documents and Settings\818\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe (Matsushita Electric Industrial Co., Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Easy-WebPrint Add To Print List - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint High Speed Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Preview - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O8 - Extra context menu item: Easy-WebPrint Print - C:\Program Files\Canon\Easy-WebPrint\Resource.dll ()
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_20.dll (Sun Microsystems, Inc.)
O15 - HKCU\..Trusted Domains: ([]msn in My Computer)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://go.microsoft.com/fwlink/?linkid=58813 (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab (Checkers Class)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} http://go.divx.com/plugin/DivXBrowserPlugin.cab (DivXBrowserPlugin Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-0000-0000-000000000000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1 192.168.2.1
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\818\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2003/08/27 13:43:38 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/06/16 20:16:48 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Malwarebytes
[2010/06/16 20:16:21 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/16 20:16:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/16 20:16:04 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/16 20:15:40 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/13 13:34:28 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/10 23:56:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MainType
[2010/06/10 21:05:30 | 000,000,000 | —D | C] – C:\cygwin2
[2010/06/10 17:08:32 | 000,000,000 | —D | C] – C:\cygwin
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Proxima Software
[2010/06/10 00:18:40 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\Obsidium
[2010/06/09 21:42:35 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Application Data\FontCreator
[2010/06/07 18:27:05 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Desktop\rks_trial002a
[2010/05/22 22:06:54 | 000,000,000 | —D | C] – C:\Documents and Settings\818\Local Settings\Application Data\Temp

========== Files - Modified Within 30 Days ==========

[2010/06/16 21:55:27 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/16 21:55:24 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/06/16 21:54:31 | 007,340,032 | —- | M] () – C:\Documents and Settings\818\ntuser.dat
[2010/06/16 21:54:00 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\818\ntuser.ini
[2010/06/16 21:53:35 | 004,233,466 | -H– | M] () – C:\Documents and Settings\818\Local Settings\Application Data\IconCache.db
[2010/06/16 21:11:03 | 000,000,970 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/06/16 20:16:24 | 000,000,707 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/16 20:06:25 | 000,056,677 | —- | M] () – C:\Documents and Settings\818\Desktop\server.py
[2010/06/16 19:39:24 | 000,016,054 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.pyc
[2010/06/16 19:34:28 | 000,040,704 | —- | M] () – C:\Documents and Settings\818\Desktop\game_sprite_classes.py
[2010/06/16 19:26:05 | 000,018,270 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.pyc
[2010/06/16 19:25:48 | 000,045,527 | —- | M] () – C:\Documents and Settings\818\Desktop\sprite_class.py
[2010/06/15 22:44:22 | 000,026,624 | —- | M] () – C:\Documents and Settings\818\My Documents\Animal Dichotomous Key.doc
[2010/06/15 22:40:27 | 000,163,328 | —- | M] () – C:\Documents and Settings\818\My Documents\Fungus.ppt
[2010/06/15 22:11:00 | 000,000,918 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/06/15 16:34:48 | 007,281,152 | —- | M] () – C:\Documents and Settings\818\Desktop\TTest.avi
[2010/06/15 16:16:56 | 000,007,539 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.pyc
[2010/06/15 00:23:06 | 000,020,050 | —- | M] () – C:\Documents and Settings\818\Desktop\game_attack_classes.py
[2010/06/13 18:55:17 | 000,031,744 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian Gray PresentationB.doc
[2010/06/13 18:48:25 | 018,911,744 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/13 18:45:51 | 000,128,447 | —- | M] () – C:\Documents and Settings\818\My Documents\black mirror.gif
[2010/06/13 17:52:53 | 000,030,720 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian Gray Presentation.doc
[2010/06/12 18:38:20 | 000,028,640 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/06/12 18:30:49 | 014,957,056 | —- | M] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/12 12:55:26 | 062,861,312 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2010/06/12 11:02:48 | 000,129,296 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/06/11 18:32:55 | 000,000,791 | —- | M] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/11 17:56:29 | 000,089,088 | —- | M] () – C:\Documents and Settings\818\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/06/11 17:48:03 | 000,000,514 | —- | M] () – C:\Documents and Settings\818\Application Data\turing_files.ini
[2010/06/11 00:35:02 | 000,000,151 | —- | M] () – C:\WINDOWS\fcp5.cfg
[2010/06/10 21:46:45 | 000,000,154 | —- | M] () – C:\WINDOWS\mt3.cfg
[2010/06/10 00:18:40 | 000,001,026 | —- | M] () – C:\WINDOWS\win.ini
[2010/06/08 17:16:31 | 000,002,279 | —- | M] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/06/08 16:17:01 | 000,003,914 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.pyc
[2010/06/07 23:30:50 | 000,005,292 | —- | M] () – C:\Documents and Settings\818\Desktop\game_maps.py
[2010/06/07 00:29:25 | 000,303,685 | —- | M] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/05/30 13:09:39 | 023,769,026 | —- | M] () – C:\Documents and Settings\818\Desktop\absurd64.zip
[2010/05/27 21:51:20 | 000,027,136 | —- | M] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/27 21:00:42 | 000,022,528 | —- | M] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/27 17:53:17 | 000,139,264 | —- | M] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:15:26 | 000,033,792 | —- | M] () – C:\Documents and Settings\818\My Documents\The Picture of Dorian Gray.doc
[2010/05/23 10:24:49 | 000,040,441 | —- | M] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/18 21:25:45 | 000,001,634 | —- | M] () – C:\Documents and Settings\818\Desktop\config.py

========== Files Created - No Company Name ==========

[2010/06/16 20:16:24 | 000,000,707 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/15 22:40:26 | 000,163,328 | —- | C] () – C:\Documents and Settings\818\My Documents\Fungus.ppt
[2010/06/15 21:58:25 | 000,026,624 | —- | C] () – C:\Documents and Settings\818\My Documents\Animal Dichotomous Key.doc
[2010/06/15 16:34:56 | 007,281,152 | —- | C] () – C:\Documents and Settings\818\Desktop\TTest.avi
[2010/06/13 18:45:51 | 000,128,447 | —- | C] () – C:\Documents and Settings\818\My Documents\black mirror.gif
[2010/06/13 17:54:35 | 000,031,744 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian Gray PresentationB.doc
[2010/06/13 15:25:44 | 000,030,720 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian Gray Presentation.doc
[2010/06/12 18:31:24 | 018,911,744 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian GrayB.ppt
[2010/06/12 12:50:27 | 014,957,056 | —- | C] () – C:\Documents and Settings\818\My Documents\Dorian Gray.ppt
[2010/06/11 18:32:54 | 000,000,791 | —- | C] () – C:\Documents and Settings\All Users\Desktop\SUPERAntiSpyware Free Edition.lnk
[2010/06/10 21:46:45 | 000,000,154 | —- | C] () – C:\WINDOWS\mt3.cfg
[2010/06/09 21:43:00 | 000,000,151 | —- | C] () – C:\WINDOWS\fcp5.cfg
[2010/06/07 00:29:23 | 000,303,685 | —- | C] () – C:\Documents and Settings\818\Desktop\realistic_rpg_icons_spells.jpg
[2010/05/27 17:45:49 | 000,139,264 | —- | C] () – C:\Documents and Settings\818\My Documents\Repetition.ppt
[2010/05/26 21:32:01 | 000,022,528 | —- | C] () – C:\Documents and Settings\818\My Documents\The Children are Laughing.doc
[2010/05/24 12:53:01 | 000,027,136 | —- | C] () – C:\Documents and Settings\818\My Documents\Poem Analysis.doc
[2010/05/23 10:24:47 | 000,040,441 | —- | C] () – C:\Documents and Settings\818\My Documents\mystic_fighters_logo.png
[2010/05/22 22:08:17 | 000,002,279 | —- | C] () – C:\Documents and Settings\818\Desktop\Google Chrome.lnk
[2010/05/22 22:06:52 | 000,000,970 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005UA.job
[2010/05/22 22:06:51 | 000,000,918 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1845922304-2555736724-1756191149-1005Core.job
[2010/05/18 21:15:52 | 000,001,634 | —- | C] () – C:\Documents and Settings\818\Desktop\config.py
[2009/06/01 21:16:05 | 000,000,031 | —- | C] () – C:\WINDOWS\Caligari.ini
[2009/05/14 22:23:40 | 000,008,704 | —- | C] () – C:\WINDOWS\System32\CNMVS74.DLL
[2008/05/19 14:12:46 | 000,000,051 | —- | C] () – C:\WINDOWS\GunzLauncher.INI
[2008/04/29 20:58:46 | 000,041,296 | —- | C] () – C:\WINDOWS\System32\xfcodec.dll
[2007/12/31 13:22:28 | 000,000,000 | —- | C] () – C:\WINDOWS\NDSTray.INI
[2007/12/30 12:55:53 | 000,000,294 | -HS- | C] () – C:\WINDOWS\System32\bcdnfblg.ini
[2007/12/23 14:48:05 | 000,000,096 | —- | C] () – C:\WINDOWS\wininit.ini
[2007/03/05 13:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2007/02/16 18:53:57 | 000,001,066 | —- | C] () – C:\WINDOWS\pae.ini
[2007/02/03 11:59:04 | 000,050,127 | —- | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2007/01/05 15:17:01 | 000,210,944 | —- | C] () – C:\WINDOWS\System32\MSVCRT10.DLL
[2007/01/05 15:17:01 | 000,000,149 | —- | C] () – C:\WINDOWS\KPCMS.INI
[2006/09/16 15:30:28 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2006/07/19 16:31:57 | 000,000,000 | —- | C] () – C:\WINDOWS\CeEKey.INI
[2006/07/16 12:56:28 | 000,001,135 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2006/07/12 14:18:29 | 000,006,528 | —- | C] () – C:\WINDOWS\System32\drivers\Tbiosdrv.sys
[2006/07/12 14:18:13 | 000,128,113 | —- | C] () – C:\WINDOWS\System32\csellang.ini
[2006/07/12 14:18:13 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\csellang.dll
[2006/07/12 14:18:13 | 000,009,535 | —- | C] () – C:\WINDOWS\System32\tosmreg.ini
[2006/07/12 14:18:13 | 000,007,671 | —- | C] () – C:\WINDOWS\System32\cseltbl.ini
[2005/08/12 17:57:09 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2004/09/26 19:32:38 | 000,044,706 | —- | C] () – C:\WINDOWS\System32\ZDMLu.INI
[2004/09/26 19:25:52 | 000,023,506 | —- | C] () – C:\WINDOWS\System32\ZDMLa.INI
[2004/08/10 14:28:20 | 000,001,088 | —- | C] () – C:\WINDOWS\System32\ZDWlan.INI
[2004/03/23 19:38:00 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2004/03/05 18:00:58 | 000,155,648 | —- | C] () – C:\WINDOWS\System32\ssleay32.dll
[2004/03/05 18:00:26 | 000,827,392 | —- | C] () – C:\WINDOWS\System32\libeay32.dll
[2003/09/01 13:51:02 | 000,086,016 | —- | C] () – C:\WINDOWS\System32\Installrt2500qa.dll
[2003/08/27 21:41:48 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/08/27 20:49:36 | 000,000,426 | —- | C] () – C:\WINDOWS\System32\Px.ini
[2003/08/27 20:47:54 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\IVIresizeW7.dll
[2003/08/27 20:47:53 | 000,200,704 | —- | C] () – C:\WINDOWS\System32\IVIresizeA6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeP6.dll
[2003/08/27 20:47:53 | 000,192,512 | —- | C] () – C:\WINDOWS\System32\IVIresizeM6.dll
[2003/08/27 20:47:53 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\IVIresizePX.dll
[2003/08/27 20:47:53 | 000,020,480 | —- | C] () – C:\WINDOWS\System32\IVIresize.dll
[2003/08/27 20:25:44 | 000,000,000 | —- | C] () – C:\WINDOWS\CePMTray.INI
[2003/08/27 13:49:38 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/08/27 13:48:06 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/08/27 13:29:57 | 000,001,866 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2003/08/27 13:29:25 | 000,027,440 | —- | C] () – C:\WINDOWS\System32\drivers\secdrv.sys
[2003/07/29 19:34:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEKPolicy.dll
[2003/07/23 21:35:04 | 000,024,576 | —- | C] () – C:\WINDOWS\System32\CeEPPolicy.dll
[2003/07/23 21:03:48 | 000,090,112 | —- | C] () – C:\WINDOWS\System32\CeEPDefDat.dll
[2002/10/06 14:42:56 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2002/10/04 19:04:24 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2002/10/04 19:04:24 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2002/10/04 19:04:16 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2002/07/17 20:45:48 | 000,004,183 | —- | C] () – C:\WINDOWS\System32\drivers\TPIOMngr.sys
[1999/01/22 12:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL

========== Files - Unicode (All) ==========
[2008/01/05 15:00:42 | 000,000,000 | —D | M](C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft
(C:\Program Files\Common Files\M?crosoft) – C:\Program Files\Common Files\Mіcrosoft

========== Alternate Data Streams ==========

@Alternate Data Stream - 99 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:84098FD3
@Alternate Data Stream - 88 bytes -> C:\Auth.prof:SummaryInformation
@Alternate Data Stream - 498 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DD0CE449
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0F8F5844
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >

OTL fix log:

OTL Extras logfile created on: 6/13/2010 11:32:26 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Documents and Settings\818\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

478.00 Mb Total Physical Memory | 228.00 Mb Available Physical Memory | 48.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.53 Gb Total Space | 49.12 Gb Free Space | 65.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: YOUR-TH3IEUQTQB
Current User Name: 818
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html [@ = Opera.HTML] – C:\Program Files\Opera\opera.exe (Opera Software)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
https [open] – "C:\Program Files\Opera\opera.exe" (Opera Software)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"1900:UDP" = 1900:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22008

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call – (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Orbitdownloader\orbitnet.exe" = C:\Program Files\Orbitdownloader\orbitnet.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\Program Files\Orbitdownloader\orbitdm.exe" = C:\Program Files\Orbitdownloader\orbitdm.exe:*:Disabled:Orbit – (Orbitdownloader.com)
"C:\WINDOWS\Downloaded Program Files\PurpleBean.exe" = C:\WINDOWS\Downloaded Program Files\PurpleBean.exe:*:Disabled:PurpleBean.exe – ()
"C:\Program Files\ijji\ijji REACTOR\REACTOR.exe" = C:\Program Files\ijji\ijji REACTOR\REACTOR.exe:*:Disabled:Reactor Application – File not found
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call – (Microsoft Corporation)
"C:\Python31\pythonw.exe" = C:\Python31\pythonw.exe:*:Enabled:pythonw – ()
"C:\Program Files\Kaiba Corp VDS\KCVDS.exe" = C:\Program Files\Kaiba Corp VDS\KCVDS.exe:*:Enabled:KCVDS – (Kaiba Corp)
"C:\cygwin\bin\XWin.exe" = C:\cygwin\bin\XWin.exe:*:Enabled:XWin – ()


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2AFDE05E-934B-4A3A-B6A8-809A7A654EF8}" = Toshiba Registration
"{2FCE4FC5-6930-40E7-A4F1-F862207424EF}" = InterVideo WinDVD Creator 2
"{3248F0A8-6813-11D6-A77B-00B0D0150030}" = J2SE Runtime Environment 5.0 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}" = McAfee SiteAdvisor
"{3ad61ee5-81d2-4d7e-adef-da1dd37277d1}" = Python 3.1
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3CF0858D-1AC5-4308-9DE7-AD15288A8BDC}" = TOSHIBA Console
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49371ACC-929A-48BB-AA5E-A35FE3D0CA5F}" = WLAN
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{666CF041-77BE-414E-9A9D-0A227E9B48F8}" = Norton™ Security Scan
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{8318FEFD-F467-44D6-82B8-129374BFE9B1}" = Opera 9.62
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Extreme Graphics Driver
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}" = Realtek Fast Ethernet Adapter Driver
"{98736A65-3C79-49EC-B7E9-A3C77774B0E6}" = Google SketchUp 6
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}" = DVD-RAM Driver
"{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = ALPS Touch Pad Driver
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{AC76BA86-7AD7-1033-7B44-A81000000003}" = Adobe Reader 8.1.0
"{B43357AA-3A6D-4D94-B56E-43C44D09E548}" = Microsoft .NET Framework (English)
"{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"{BDD83DC9-BEE9-4654-A5DA-CC46C250088D}" = TOSHIBA ConfigFree
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition
"{DDC146FA-73E0-4FA1-A353-841EA14BF600}" = Drag'n Drop CD+DVD
"{EC86822D-3A20-11D5-801B-00E029348F40}" = SMSC IrCC Driver V5.1.2462.0 (WinXP)
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Agnitum Outpost Firewall 1.0" = Agnitum Outpost Firewall 1.0
"Avira AntiVir Desktop" = Avira AntiVir Personal - Free Antivirus
"CANONBJ_Deinstall_CNMCP74.DLL" = Canon iP2200
"Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint
"Easy-PrintToolBox" = Canon Utilities Easy-PrintToolBox
"Easy-WebPrint" = Easy-WebPrint
"GraphicsGale FreeEdition_is1" = GraphicsGale FreeEdition version 1.93.12
"Hamachi" = Hamachi 1.0.3.0
"InstallShield_{107C7E59-F4CF-444F-BCCC-8223137D1AD1}" = TouchPad On/Off Utility
"InstallShield_{41DBA4F1-E295-41B3-9922-7B346C5B8EBF}" = TOSHIBA Hotkey Utility
"InstallShield_{B83DA26B-5237-41E8-8612-8F3F63F69811}" = TOSHIBA Power Management Utility
"Kaiba Corp VDS_is1" = Kaiba Corp Virtual Duel System 1.16
"Messenger Plus! Live" = Messenger Plus! Live
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework Full v1.0.3705 (1033)" = Microsoft .NET Framework (English) v1.0.3705
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"Orbit_is1" = Orbit Downloader
"RPG Maker 2003_is1" = RPG Maker 2003 v1.08
"RPG Maker VX RTP_is1" = RPG Maker VX RTP
"RPG Maker VX_is1" = RPG Maker VX
"SCAR 2.03_is1" = SCAR CDE 2.03
"Screen Recorder Gold" = Screen Recorder Gold
"SpriteForge_is1" = VE1.8-R1.9
"SpywareBlaster_is1" = SpywareBlaster v3.5.1
"SpywareGuard_is1" = SpywareGuard v2.2
"SystemRequirementsLab" = System Requirements Lab
"TOSHIBA Software Modem" = TOSHIBA Software Modem
"Toshiba Tbiosdrv Driver" = Toshiba Tbiosdrv Driver
"TrueCrypt" = TrueCrypt
"VLC media player" = VLC media player 0.9.9
"WampServer 2_is1" = WampServer 2.0
"Windows XP Service Pack" = Windows XP Service Pack 2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WLAN 802.11g USB2.0 Utility" = WLAN 802.11g USB2.0 Utility
"WordWeb" = WordWeb

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 6/11/2010 5:11:22 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 6:11:21 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 6:26:36 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/11/2010 6:29:40 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Application Hang | ID = 1002
Description = Hanging application SUPERAntiSpyware.exe, version 4.15.0.1000, hang
module hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 6/11/2010 7:11:20 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/11/2010 7:36:38 PM | Computer Name = YOUR-TH3IEUQTQB | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Error - 6/12/2010 9:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/12/2010 10:11:06 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/13/2010 1:11:07 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

Error - 6/13/2010 2:11:05 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Google Update | ID = 20
Description =

[ System Events ]
Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 6:07:30 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7023
Description = The Application Management service terminated with the following error:
%%126

Error - 6/11/2010 7:35:53 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 11:03:27 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 12:49:35 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 12:56:05 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/12/2010 2:34:19 PM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2

Error - 6/13/2010 12:34:44 AM | Computer Name = YOUR-TH3IEUQTQB | Source = Service Control Manager | ID = 7000
Description = The NTPort Library Driver service failed to start due to the following
error: %%2


< End of report >

Malwarebyte fix:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4207

Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

6/16/2010 9:53:17 PM
mbam-log-2010-06-16 (21-53-17).txt

Scan type: Quick scan
Objects scanned: 137666
Time elapsed: 11 minute(s), 41 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 8
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 2
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\V71IQL7HI7 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\M5T8QL3YW3 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
C:\Program Files\WinBudget (Adware.Admedia) -> Quarantined and deleted successfully.
C:\Program Files\WinBudget\bin (Adware.Admedia) -> Quarantined and deleted successfully.

Files Infected:
(No malicious items detected)

There thats all of them!
Hi mystic_hs,

Looks pretty good so far.

You posted the OTL Extra.txt instead of the OTL fix log. Please open Windows Explorer (right click your start button and click explore)
  • Navigate to this folder C:\_OTL\MovedFiles
  • In the right hand panel locate a file similar to 6162010 212037.log
  • Yours may be slightly different. The numbers represent the date and time the fix was ran.
Please post it's contents.

One more scan just to check our handiwork.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Please go to Kaspersky website and perform an online antivirus scan.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions.
  • You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As….
  • Change the Files of type to Text file (.txt)
  • Set the Save In to Desktop
  • click the Save button.
  • Please post this log in your next reply.
Please post back with
  • OTL fix log
  • Kaspersky log
Any problems?

Thanks
OTL fix log: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B6FF8C4D-6FAF-3B2F-DC5F-3AE671F70C97}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e9acaeed-f5e5-40ed-bc1a-7ecd39c46ef9}\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\M5T8QL3YW3 deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmnmmli\ deleted successfully. C:\WINDOWS\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job moved successfully. C:\WINDOWS\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: 818 ->Temp folder emptied: 666318860 bytes ->Temporary Internet Files folder emptied: 11484795 bytes ->Java cache emptied: 180151074 bytes ->FireFox cache emptied: 133950007 bytes ->Google Chrome cache emptied: 352417902 bytes ->Opera cache emptied: 12389825 bytes ->Flash cache emptied: 25751 bytes User: Administrator ->Temporary Internet Files folder emptied: 32768 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32969 bytes User: Guest ->Temp folder emptied: 1144 bytes ->Temporary Internet Files folder emptied: 261665 bytes ->FireFox cache emptied: 11765919 bytes ->Opera cache emptied: 165567 bytes ->Flash cache emptied: 1009 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 271468 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner User: postgres ->Temporary Internet Files folder emptied: 32768 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 68623 bytes %systemroot%\System32 .tmp files removed: 182944 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 14732680 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 14775970 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1,334.00 mb OTL by OldTimer - Version 3.2.6.0 log created on 06132010_133428 Files\Folders moved on Reboot… File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\ZQONBHWH\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\ZQONBHWH\imgres[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\ZQONBHWH\imgres[2]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\ZQONBHWH\neopets[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\Y9WLYD0H\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\V9QM5YZR\search[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\TF3JL5CE\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\ads[2]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\ads[3]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\ads[4]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\translate_t[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\SY0H47UL\~Neo____Zafara[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\OZSB2JIV\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\OL23456V\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\NDDZ2621\index[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\MXLQZ69W\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\KND7267X\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\HIKAYXX2\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\GZG92N63\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\GBSBUF83\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\G71VQ6Z9\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\G5UVWDEB\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\EXKNONI7\search[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\CXO3GZE9\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\C78FAN07\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\977LFHZK\search[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\91B3YWUD\customise[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\91B3YWUD\images[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\91B3YWUD\~Neo____Zafara[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\8HIRSHMR\search[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\8DWYYS85\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\6MYVX2UR\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\6MYVX2UR\search[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\4T27CD2V\google[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\4FI1Q7G5\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\4FI1Q7G5\images[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\2HIF2NOJ\ads[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\2HIF2NOJ\ads[2]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\2HIF2NOJ\ads[3]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\2HIF2NOJ\monroe&r=67[1]. not found! File\Folder C:\Documents and Settings\818\Local Settings\Temporary Internet Files\Content.IE5\01EBWXQ3\ads[1]. not found! Registry entries deleted on Reboot… Do I have to do the Kaspersky Online Scan? I tried it once using Firefox 3.6 after 2 hours it finally finished updating the database and it got stuck for 30 minutes, so I pressed refresh hoping the files can be retrieved, but it seems like it restarts back to the beginning, back to 0%! :wacko:
Hi mystic_hs,


Kaspersky has a very good detection rate and online scans are an important part of malware removal. Malware can use legitamate filenames and file sizes. The tools we use for the most part only show the filenames and reported filesize not if they are infected.

That does seem like a long time to download the database unless you have a very slow connection or haven't disabled your onboard security programs.

Try this one instead. It's easier if you use Internet Explorer.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You must use Internet Explorer for this scan.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • Re-enable your Antivirus software.
  • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt. or C:\Program Files\ESET\log.txtWe will need this later.
Please post back with the ESET log.
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=54be03e86e198b49916d31072d8ac465 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-06-24 04:45:24 # local_time=2010-06-24 12:45:24 (-0500, Eastern Daylight Time) # country="United States" # lang=9 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=512 16777215 100 0 0 0 0 0 # compatibility_mode=1797 16775141 100 100 0 51343138 0 0 # compatibility_mode=6912 16777215 100 0 77268388 77268388 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=85541 # found=1 # cleaned=0 # scan_time=4553 C:\WINDOWS\system32\bcdnfblg.ini Win32/Adware.Virtumonde.NEO application 00000000000000000000000000000000 I

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI